Description
Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization bypass
Action: Patch
AI Analysis

Impact

Ghost 4.3.0 through 6.57.x contains an authorization flaw where staff users with lower privileges can use staff tokens to edit posts beyond their allowed scope. This allows an attacker who has staff credentials or can obtain a staff token to perform unauthorized content modifications, compromising the integrity of published articles and potentially facilitating defacement or misinformation.

Affected Systems

The vulnerability is present in Ghost CMS products distributed by TryGhost, specifically Ghost versions 4.3.0 up to 6.57.x. Versions 6.58.0 and newer contain the fix. Organizations running these older releases are at risk if staff tokens are enabled and staff privileges are assigned.

Risk and Exploitability

With a CVSS score of 5.3 the severity is moderate, and the lack of an EPSS score or KEV listing indicates no known exploitation of this flaw yet. The most likely attack vector is via staff tokens, meaning an adversary with staff credentials or the ability to acquire a staff token can bypass editing restrictions. The flaw does not require elevation beyond staff roles, so the primary impact is on content integrity rather than full system compromise.

Generated by OpenCVE AI on October 1, 2026 at 14:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading Ghost to version 6.58.0 or later
  • Rotate or revoke all staff tokens that may have been issued before the patch
  • Review and enforce staff role policies to ensure that post editing rights match staff responsibilities, and monitor logs for any unauthorized edits

Generated by OpenCVE AI on October 1, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.
Title Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-863
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:33:50.258Z

Reserved: 2026-09-30T10:59:00.638Z

Link: CVE-2026-103273

cve-icon Vulnrichment

Updated: 2026-10-01T13:33:47.189Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:22.730

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:00:12Z

Weaknesses